Pilot Crewroom
Back to home

Privacy Policy

Your practice data, explained.

This Policy explains what Pilot Crewroom processes when you visit, create an account, buy session credits, speak in an AI practice room, save coaching, contact support, or exercise a privacy right.

Last updated 18 July 2026

1. Controller, scope and contact route

Pilot Crewroom's individual Polish Operator is the controller of the personal data processed to operate pilotcrewroom.com (the “Controller”, “we”, “us” or “our”). The Controller's legal identity is stated in Section 8. For privacy enquiries or to exercise a right, email [email protected].

This Policy covers Pilot Crewroom's public pages, customer accounts, practice service, support and product records. Link, Stripe, Google and other providers may act as separate controllers for parts of their own services; their notices apply to that independent processing.

  • Email the Controller

2. Data we collect

  • Account and profile data: name, email address, email-verification status, optional avatar settings, sign-in method, encrypted Google account tokens where Google sign-in is used, session records and account timestamps. Passwords are salted and hashed by the authentication system and are not stored as readable text.
  • Legal and security records: the versions of the Terms, Privacy Policy and Cookie Policy accepted or acknowledged, acceptance method and time; the version and server time of a pre-checkout request for immediate digital-service performance and refund-policy acknowledgement; login and rate-limit data; IP address and browser/network signals; request ID, method and privacy-scrubbed route; administrator and account-deletion audit records.
  • Practice data: chosen scenario, room and timing state, microphone audio while a room is live, speech transcription, synthetic-participant transcript, working metrics, contribution counts, saved transcript, assessment scores, evidence quotes, coaching report and technical AI-usage metadata.
  • Purchase and entitlement data: package, price and currency, checkout state, provider customer/order/payment references, payment status, refund status, session-credit balances, grant and expiry dates, credit-to-session allocation records, an append-only credit ledger and signed-webhook evidence. We do not receive or store complete card numbers or card security codes.
  • Support data: the email address and contents of messages you send, the order or account details needed to investigate a request, and our response.
  • Public-page and infrastructure data: page path, referrer host, approximate country, device/browser category and performance timings where cookieless Cloudflare Web Analytics is enabled, plus operational and security logs created by Cloudflare, the host and the application.

3. Data we do not seek

We do not use advertising cookies, sell personal data, share it for cross-context behavioural advertising, build advertising profiles, collect precise device location, or use voice to identify you biometrically or infer emotion. Pilot Crewroom does not save a raw microphone recording as an audio file, although OpenAI processes live audio and may retain provider-side abuse-monitoring data as described below.

The service is not designed for special-category data, medical information, real recruitment files, confidential employer material or another person's personal data. Avoid speaking or pasting such information into a room or support message. If it is necessary to contact us about an incident, send only the minimum information required.

4. Why we process data and our legal bases

  • Contract: to create and secure your account; verify email; provide sign-in, session credits, live simulation, transcription, saved history, coaching, account controls, transactional email and product support; and take steps you request before entering a contract.
  • Legal obligations: to provide consumer and privacy rights, respond to lawful requests, maintain required tax, accounting, payment, consent and complaint records, and establish or demonstrate compliance.
  • Legitimate interests: to prevent fraud and abuse, secure the service, enforce credit and access controls, diagnose failures, keep minimal audit trails, defend legal claims, understand aggregate public-page performance and improve reliability. We balance these interests against your rights and minimise the data used.
  • Consent: we rely on consent only where an optional activity legally requires it. Browser microphone permission lets you control device access but the service processing needed to run a room is otherwise performed under the contract. Accepting the Terms or acknowledging this Policy is not consent to unrelated processing or marketing.

5. Microphone, transcription and OpenAI

  • When you enter a live room and allow microphone access, audio is sent through an encrypted WebRTC connection to an OpenAI Realtime session for voice-activity detection and transcription. Pilot Crewroom receives the resulting text and does not store the raw microphone audio file.
  • The evolving text transcript, scenario context and working state are sent to OpenAI to select and generate clearly identified AI-participant turns. Synthetic audio is streamed back for playback and is not stored as an audio file by Pilot Crewroom.
  • At the end of a run, the scenario, elapsed time and transcript are sent to an OpenAI assessment model to generate evidence-linked coaching. Assessment requests are configured not to create stored Responses API objects, but normal provider abuse-monitoring retention may still apply.
  • OpenAI states that API data is not used to train its models by default unless the API customer opts in. Under OpenAI's default controls, abuse-monitoring logs may contain prompts, responses, transcripts or audio-derived content and may be retained for up to 30 days, or longer where legally required or reasonably necessary to protect services or third parties. Approved reduced-retention controls may shorten this in a configured project.
  • OpenAI API data controls

6. AI coaching and automated decisions

AI produces practice scores, behavioural-marker findings, evidence quotes and suggested next actions from the transcript. The system is instructed to assess only observable candidate text and not to infer emotion, health, protected characteristics, personality or mental state. AI output can still be wrong or incomplete.

This processing does not make a decision that produces legal or similarly significant effects. Pilot Crewroom does not decide whether you are hired, certified or admitted to training, does not send reports to airlines or employers, and does not use scores to change prices or eligibility. You choose whether and how to use the coaching and may contact support to question an output.

7. Payments and Link as Merchant of Record

A payment form hosted by Stripe is embedded inside Pilot Crewroom. Link is displayed as the Merchant of Record for Stripe Managed Payments transactions and processes payment credentials, billing details, device and interaction signals, indirect tax, receipts, refunds, disputes and transaction support under its own notices and payment terms. Pilot Crewroom cannot read payment credentials entered into the isolated payment frame.

Pilot Crewroom receives only the customer and transaction references, package, amount, currency and payment/refund status needed to provide credits, reconcile the order, prevent fraud and provide support. Verified, idempotently claimed Stripe webhook events are the only payment messages that can change purchased entitlements.

Link and Stripe may act as independent controllers for transaction, tax, fraud, legal and support purposes. A request to delete your Pilot Crewroom account does not by itself delete a Link account or records Link must retain as Merchant of Record. Contact Link or us and we will direct or coordinate the request as appropriate.

  • Link privacy notice
  • Stripe privacy centre
  • Link order and transaction support

8. Controller identity

The Controller is Aleksander Koupeloglou, operating Pilot Crewroom as an individual established in Poland.

Email [email protected] for any privacy question, rights request or complaint. This address reaches the Controller directly for purposes of this Policy.

  • Email the Controller

9. Other recipients and service providers

  • OVHcloud provides the EU-hosted virtual server and OVH Zimbra SMTP delivery for account-verification, password-reset and other transactional email.
  • Cloudflare provides DNS, encrypted edge delivery, private-tunnel routing, access protection during the private preview, denial-of-service protection, filtering, rate limiting, Turnstile human-verification and cookieless public-page analytics. It processes network, device and browser signals needed for those purposes.
  • OpenAI processes live audio, transcripts, scenario context, generated synthetic speech and assessment input/output to provide the requested simulation and coaching.
  • Google processes optional OAuth sign-in. If selected, Google supplies the account identifiers and basic profile details needed to sign you in; Pilot Crewroom never receives your Google password.
  • Link and Stripe process Managed Payments transactions as described above. Professional advisers, insurers, auditors, authorities or courts receive limited information only where reasonably necessary to comply with law, protect rights or handle a claim.
  • We do not disclose your transcript or coaching to airlines, academies, recruiters, other customers or the public. There are no public posts or user-to-user content features.

10. International transfers

The primary application database is hosted on OVHcloud infrastructure in the European Union. Cloudflare, OpenAI, Google, Stripe and Link operate internationally and may process personal data outside the EEA, including in the United States.

Where GDPR transfer restrictions apply, we use the provider's applicable data-processing terms and a recognised transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You may contact us for information about the safeguard relevant to a particular transfer.

11. Retention

  • Account and profile data are kept while the account is open. Authentication sessions can remain valid for up to 30 days unless you sign out, reset the password, delete the account or the session is revoked earlier.
  • Saved transcripts, run metrics and coaching reports remain until you delete the individual run or the account. Deleting a run removes it from the active database. A live run that is not saved may still be present temporarily in client/session state and in provider abuse-monitoring data.
  • When you delete the account, the active database removes sign-in accounts and sessions, OAuth credentials, avatar settings, saved runs, transcripts and assessments, and replaces direct identity fields with a deleted-account marker. Nightly database backups are automatically aged out after 14 days.
  • After account deletion we retain minimised, pseudonymous payment, credit-ledger, legal-acceptance, security, deletion and audit evidence for the periods required by tax, accounting, consumer-protection, fraud-prevention and legal-claims law. This can include a one-way email hash and provider/order references. Access is restricted and the records are not used for marketing or coaching.
  • Application request logs exclude query strings and bodies and rotate by storage volume; Cloudflare, the email provider, OpenAI, Google, Stripe and Link retain their own operational, security and legal records under their policies. OpenAI's default API abuse-monitoring period is described above.
  • If law requires preservation, a dispute is open or deletion would impair another person's rights, the relevant record may be held longer and isolated from ordinary use. Data that has been irreversibly aggregated so it no longer identifies anyone may be retained for service statistics.

12. Your controls and data-protection rights

Email [email protected] to exercise a right. We may request proportionate information to verify the requester and protect the account. We normally respond within one month under GDPR; that period can be extended by up to two further months for a complex or numerous request, in which case we will explain the extension within the first month. Rights and time limits vary by jurisdiction.

  • Access and portability: ask for confirmation and a copy of your personal data in a commonly used electronic format where applicable.
  • Rectification: update your profile in Account settings or ask us to correct inaccurate data.
  • Erasure: delete an individual run from its report, permanently delete the account in Account settings, or ask us to erase other data, subject to lawful retention exceptions.
  • Restriction and objection: ask us to restrict processing or object to processing based on legitimate interests. You have an absolute right to object to direct marketing; Pilot Crewroom currently sends no direct marketing.
  • Consent: where a future optional activity relies on consent, withdraw it as easily as it was given. Withdrawal does not affect earlier lawful processing. Core contract or legal-obligation processing may continue on another lawful basis.
  • Complaint: lodge a complaint with the data-protection authority where you live, work or believe an infringement occurred. You can find EEA authorities through the European Data Protection Board. UK users may contact the Information Commissioner's Office.
  • Email a privacy request
  • European data-protection authorities
  • UK Information Commissioner's Office

13. Cookies and similar technologies

Pilot Crewroom uses strictly necessary authentication, security and preference cookies for signed-in features and for recording that the necessary-cookie notice was acknowledged. Cloudflare Turnstile protects sensitive account actions, and the embedded Stripe form can use its own necessary payment and fraud-prevention storage. Public-page Cloudflare Web Analytics is configured without analytics cookies, local storage or fingerprinting.

The Cookie Policy lists purposes, lifetimes and controls. Because authentication cookies are necessary to provide an account safely, disabling them means signed-in features will not work; public and legal pages remain readable without signing in.

  • Read the Cookie Policy

14. Security

We use measures appropriate to the service, including HTTPS, a private origin tunnel, network filtering, rate limits, short-lived simulation credentials, server-side access checks, password hashing, encrypted OAuth tokens, HttpOnly cookies, webhook signatures, append-only billing and legal records, restricted administrator access, database backups and privacy-scrubbed application logging.

No service can guarantee absolute security. If a personal-data breach is likely to risk people's rights and freedoms, we will notify the competent authority without undue delay and, where GDPR applies, where feasible within 72 hours of awareness. If it is likely to create a high risk, we will also notify affected people without undue delay unless a legal exception applies.

15. Adults only

Pilot Crewroom is intended for adults aged 18 or over and is not directed to children. We do not knowingly create accounts for or collect personal data from children. If you believe a child has provided personal data, contact us so we can investigate and delete it where required.

16. Changes and contact

We may update this Policy when the service, providers or law changes. The current version and effective date will remain on this page. We will give reasonable notice of material changes and request a new acknowledgement or consent where legally required. Previous versions are available on request.

For a privacy question, rights request or complaint, email [email protected]. Please do not include passwords, complete payment-card details or unnecessary transcript content.

  • Contact Pilot Crewroom about privacy